Insecure deserialization In org.python:jython-standalone

Description

Deserialization of Untrusted Data in Jython Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions
FLAT-TNWCZ – Vulnerability | Fluid Attacks Database